CVE-2024-53150
Linux Kernel Out-of-Bounds Read Vulnerability
- 대응 우선순위
- 최우선
- CVSS
- 7.1
- EPSS
- 1.32% 백분위 67.4% · 2026.06.27 기준
- CISA KEV
- 등록
- 조치 기한
- 2025.04.30
- 공개일
- 2024.12.24
CISA KEV에 등록된 실제 악용 확인 취약점
In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix out of bounds reads when finding clock sources The current USB-audio driver code doesn't check bLength of each descriptor at traversing for clock descriptors. That is, when a device provides a bogus descriptor with a shorter bLength, the driver might hit out-of-bounds reads. For addressing it, this patch adds sanity checks to the validator functions for the clock descriptor traversal. When the descriptor length is shorter than expected, it's skipped in the loop. For the clock source and clock multiplier...
공급사 Linux
제품 Kernel
영향 버전 b8e4f1fdfa422398c2d6c47bfb7d1feb3046d70a, 9feeaa50e5b4b0b71259d918a36ecf9059e60796, 3b17a13b687ae99939dc94a4ae01fbc34f68decc, 4.19.84, 5.3.11, 5.4, 11.0, < 5.4.287, >= 5.5 < 5.10.231, >= 5.11 < 5.15.174, >= 5.16 < 6.1.120, >= 6.2 < 6.6.64, >= 6.7 < 6.11.11, >= 6.12 < 6.12.2
수정 버전 5.4.287, 5.10.231, 5.15.174, 6.1.120, 6.6.64, 6.11.11, 6.12.2
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
조치 기한: 2025.04.30CVSS 벡터 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
CWE CWE-125
KEV 등록일 2025.04.09
랜섬웨어 캠페인 사용 미확인
CISA 비고 This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. For more information, please see: https://lore.kernel.org/linux-cve-announce/2024122427-CVE-2024-53150-3a7d@gregkh/ ; https://source.android.com/docs/security/bulletin/2025-04-01 ; https://nvd.nist.gov/vuln/detail/CVE-2024-53150
EPSS 데이터 기준일 2026.06.27